1. What we collect
From registered users (advertiser / web)
- Email and password hash (bcrypt)
- IP address and user-agent at login (for security)
- Registration date, last login
- USDT wallet address (for payouts only)
- Telegram chat_id (optional, for notifications)
From visitors of sites where our widget is installed
- IP hash(SHA-256, one-way transformation, IP cannot be recovered)
- Geo by IP at country level (geolocation for targeting)
- User-agent → device type, OS, browser
- Browser fingerprint (canvas+WebGL hash) — for anti-fraud, not for ad identification
- Referer (domain of the site where the ad was seen)
- Cookie-ID for frequency cap (show no more than N times per day)
We do NOT collect:name, email, phone, address, passport, banking details of site visitors. We don't peek at what you enter in forms. We don't track movement across other sites without our widget.
2. Why
- Showing relevant adsby geo and site category
- Anti-fraud- filtering out bots, proxies, click farms
- Frequency cap- do not show one creative 100 times to the same user
- Billing- fair impression and click counting for advertiser/publisher billing
- Analytics— dashboards for advertiser and publisher
3. Visitor data from publishers' websites
Sladu technically doesn't know who these people are as individuals. We only see an anonymized set of signals: hashed IP + user-agent + browser fingerprint. This is enough for anti-fraud and targeting, but not enough for de-anonymization.
If you are a visitor to a site where our widget is installed and want us to stop recognizing you — clear the site cookies or enable Do Not Track mode in your browser (we respect it).
4. Third parties
We don't sell data.This is a matter of principle, not marketing.
We share anonymized data only with:
- IPQualityScore- we send the IP for proxy/VPN/datacenter check (anti-fraud). They don't know who the user is, only the IP.
- Anthropic Claude- creative images/videos are sent to AI Vision for moderation. We do not send visitor data.
- HeyGen- if the advertiser generated an AI video via our AI Studio, the script is sent to HeyGen for rendering.
- OpenRTB partners- when header bidding, we share anonymized auction context (geo, format, block size) in accordance with the IAB standard.
5. Storage and security
- Servers in the Netherlands, physically at EUROHOSTER data center
- PostgreSQL for users and campaigns, ClickHouse for analytics
- TLS 1.3 encryption for all connections
- Passwords via bcrypt with cost factor 12
- Daily backup, 30-day retention
- Prod DB access is limited to two senior engineers with MFA
6. Your rights (GDPR + 152-FZ)
If you're in the EU, Russia, or another jurisdiction with data protection laws — you have rights:
- Access- request all your data by email
dpo@sladu.net, we'll respond within 30 days - Deletion- delete account in
/cabinet/profileor by email. Financial records are kept for 5 years (required by law). - Fix- edit data in the dashboard yourself
- Transfer- export your data in JSON on request
- Objection- you can opt out of using your data for marketing (for Sladu self-promotion, not for our clients' ads)
You can file a complaint about rights violations with the supervisory authority in your country (Roskomnadzor / EU DPA).
8. Contacts
- Data Protection Officer:
dpo@sladu.net - Telegram: @sladu_support
- Data access/deletion requests: response within 30 days
In short:minimal data, we don't sell it, we encrypt it, delete on request. If you want more detail on any point — just askdpo@sladu.net.